TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Rate my startup - CertiVox's PrivateSky

5 点作者 bribriinlondon将近 14 年前
I've been a long time lurker on the board, but this is my first official post. My name is Brian Spector, I'm a long time crypto geek, working in infosec for about 20 years.<p>Last week we launched a new service called PrivateSky, which is a end to end, browser to browser encryption service, for free. Our first product is the PrivateSky for Internet Explorer add-in. Yes, we will come out with Firefox and Chrome soon.<p>I'd love to see what the board thinks about what we are doing, and if so, what we could improve.<p>I hope this is the appropriate place to post this, if I'm violating policy (checked, couldn't find anything), then please do let me know and I will delete this.<p>You can get the free PrivateSky Internet Explorer add-in at:<p>https://privatesky.me<p>What does it do?<p>CertiVox's PrivateSky SaaS is a major innovation in secure inforamtion exchange. The PrivateSky for Internet Explorer Connector add-in is a whole new approach to securing confidential information posted to the web, and anyone can use it. The PrivateSky for IE add-in doesn't require multiple passwords, certificates, or complicated processes to learn. It's simple browser to browser encryption that just works. Use it to encrypt your webmail, Facebook posts and messages, LinkedIn messages and even blog posts. PrivateSky uses the AES encryption algorithm, that means it is super safe!<p>Enough with the marketing schpeel, here's what we really do:<p>We operate an encryption key management server in the cloud. Our software connects to our key server to get everyone who enrols what we call a SkyKey. You can think of this like a private key. However, we are using a new form of key agreement called non-interactive authenticated key agreement, based upon bilinear pairing mathematics. No, this is not identity based encryption, this is non-interactive key agreement. It's heady stuff, but it has suffered through 20 years of cryptanalysis and is secured by the DLP.<p>Now, the thing is, there is no public key. There is only one key, your SkyKey. But, this enables you to create "connection keys", which are regular AES 192 bit keys. The analogy I always use is this: Suppose every time you made a friend on Facebook, a worldly unique AES key was created between you and your friend, and could only be created between you and your friend.<p>That's what we've managed to do, but in your browser. Oh, and there is a boatload of key protection, rotation, etc., going on in the background.<p>Again, love to get some feedback. I'm the chief bottle washer at the moment so I can't promise to respond to feedback immediately, but will try my best.<p>Thank you for giving it a shot and please let 'er rip, the good, bad and ugly.<p>Cheers, Brian

7 条评论

bribriinlondon将近 14 年前
Hi, sorry, the description didn't come though:<p>I've been a long time lurker on the board, but this is my first official post. My name is Brian Spector, I'm a long time crypto geek, working in infosec for about 20 years.<p>Last week we launched a new service called PrivateSky, which is a end to end, browser to browser encryption service, for free. Our first product is the PrivateSky for Internet Explorer add-in. Yes, we will come out with Firefox and Chrome soon.<p>I'd love to see what the board thinks about what we are doing, and if so, what we could improve.<p>I hope this is the appropriate place to post this, if I'm violating policy (checked, couldn't find anything), then please do let me know and I will delete this.<p>You can get the free PrivateSky Internet Explorer add-in at:<p><a href="https://privatesky.me" rel="nofollow">https://privatesky.me</a><p>What does it do?<p>CertiVox's PrivateSky SaaS is a major innovation in secure inforamtion exchange. The PrivateSky for Internet Explorer Connector add-in is a whole new approach to securing confidential information posted to the web, and anyone can use it. The PrivateSky for IE add-in doesn't require multiple passwords, certificates, or complicated processes to learn. It's simple browser to browser encryption that just works. Use it to encrypt your webmail, Facebook posts and messages, LinkedIn messages and even blog posts. PrivateSky uses the AES encryption algorithm, that means it is super safe!<p>Enough with the marketing schpeel, here's what we really do:<p>We operate an encryption key management server in the cloud. Our software connects to our key server to get everyone who enrols what we call a SkyKey. You can think of this like a private key. However, we are using a new form of key agreement called non-interactive authenticated key agreement, based upon bilinear pairing mathematics. No, this is not identity based encryption, this is non-interactive key agreement. It's heady stuff, but it has suffered through 20 years of cryptanalysis and is secured by the DLP.<p>Now, the thing is, there is no public key. There is only one key, your SkyKey. But, this enables you to create "connection keys", which are regular AES 192 bit keys. The analogy I always use is this: Suppose every time you made a friend on Facebook, a worldly unique AES key was created between you and your friend, and could only be created between you and your friend.<p>That's what we've managed to do, but in your browser. Oh, and there is a boatload of key protection, rotation, etc., going on in the background.<p>Again, love to get some feedback. I'm the chief bottle washer at the moment so I can't promise to respond to feedback immediately, but will try my best.<p>Thank you for giving it a shot and please let 'er rip, the good, bad and ugly.
评论 #2727508 未加载
JangoCuni将近 14 年前
Am familiar with bilinear pairing and did not know it was available commercially! Pretty cool.. On first glance it seems cumbersome to highlight text first and then apply. Why not just automate the process for the entire note? Also how are you making sure the recreation of the connection key is authenticated?
评论 #2727085 未加载
JOnAgain将近 14 年前
I spent a few min clicking through the site I have no idea what it does, though I now understand you're like the 'whiz-bang military'. Copy needs a lot of work. Screenshots, demos, videos, something to let me know what using the service is actually like.
评论 #2727485 未加载
spreiti将近 14 年前
This is pretty neat. I will try it out as soon as there is a version for Chrome.<p>One suggestion: Decrypt the message automatically when the user opens the page. I think it's cumbersome to manually decrypt the message everytime.
评论 #2729291 未加载
bribriinlondon将近 14 年前
Coverage: <a href="http://www.pcmag.com/article2/0,2817,2388080,00.asp?kc=PCRSS05079TX1K0000992" rel="nofollow">http://www.pcmag.com/article2/0,2817,2388080,00.asp?kc=PCRSS...</a>
oliciv将近 14 年前
I didn't know what it was. I clicked the "more information" button. I still don't know what it is.
评论 #2726965 未加载
jivejones将近 14 年前
Cool idea, although internet explorer / silver light isn't my cup of tea.
评论 #2727135 未加载